Skip to content
Asset Intelligence · Product Cybersecurity

Know your products.
Keep their cybersecurity under control as they evolve.

A manufacturer does not manage one security file. It manages projects, products, equipment, variants, software versions, components, dependencies and years of change. The first challenge is therefore to keep a reliable picture of what really exists — before talking about vulnerabilities, threats or risk.

VAST structures this knowledge around Projects and Assets. Each Asset represents a product or equipment that lives in the platform, with its versions, technical composition, relationships and history. As the product evolves, VAST keeps the context teams need to search, understand the impact of a change and support the cybersecurity activities that depend on it.

Projects & Assets · Asset Inventory · Versions & Dependencies · Portfolio Search · Vulnerability & VEX · Threat & Risk · Reporting

Watch the video
The VAST journey — from product knowledge to evidence
Projects
Assets
Inventory
Versions & dependencies
Search
Vulnerabilities / VEX
Threats
Risk
CRA & Evidence

Everything starts from product knowledge. Risk and the CRA are not the starting point: they become reliable because that knowledge already exists.

FROM PORTFOLIO TO PRODUCT

Projects & Assets

Start by knowing which products exist, which project they belong to and what state they are in.

In an industrial organization, product cybersecurity cannot be managed product by product in separate files. Different teams work across several projects, often on product families that share components, suppliers or software building blocks. Without a common structure, knowledge quickly becomes fragmented.

VAST uses Projects to organize the work and Assets to represent the products or equipment that need to be secured. Users can move from a portfolio view to a project and then to a specific Asset without losing context. This hierarchy gives teams a common reference: they know which product they are discussing, which version is concerned and which information belongs to it.

The Asset becomes the reference point around which technical and cybersecurity information can evolve over time.

DEMO DATA
Portfolio · Projects · Assets
Capture produit VAST
à intégrer
ASSET MANAGER

Asset Manager & Asset Inventory

See the product as it really exists, not only as a row in an inventory.

A product name and a version number are not enough to understand its cybersecurity surface. Teams need to know what the product contains, where software runs, which applications provide product functions, what data is handled, which accounts are used, how components communicate, and how the product is maintained or updated.

The Asset Inventory provides this technical knowledge base in VAST. It brings together and connects the important product elements: **Hardware, Software and SBOM, Accounts, Data, Business Apps, Interconnections, Tools and Updates**. Dependencies and relationships between these elements gradually create a much more useful picture than a simple administrative inventory.

The goal is not documentation for its own sake. This knowledge helps teams find a dependency, understand a communication path, locate a component, place a vulnerability in context or prepare a cybersecurity assessment without rebuilding the product every time.

DEMO DATA
Asset Inventory
Capture produit VAST
à intégrer
VERSIONS · CHANGE · HISTORY

Versions & history

The product changes. Its Asset must keep telling the right story.

A new release can change several things at once: a library moves to a new version, an application changes a dependency, an interface appears, a technical account evolves, or the update mechanism is strengthened. If the inventory stays frozen, the cybersecurity work around it immediately starts losing context.

In VAST, the Asset is designed to evolve with the product. Versions and revisions preserve what was true at a given point in time while the next state is being built. Teams can understand how the product changed without overwriting its history, and cybersecurity activities can stay connected to the right technical state.

That continuity is what turns an inventory into real **Asset Intelligence**.

DEMO DATA
Asset · Versions & History
Capture produit VAST
à intégrer
UNDERSTAND WHAT DEPENDS ON WHAT

Dependencies & product relationships

A technical dependency is more than an SBOM entry.

Knowing that a package is present is useful. Knowing **where it is used, what depends on it and which products contain it** is much more valuable. In connected and embedded products, the same library, component or technology may appear across several applications, versions and projects.

VAST keeps the useful relationships around the Asset so product composition does not remain a flat list. Teams can explore dependencies and understand the possible consequences of a change, obsolescence issue or supply-chain problem much faster.

When the question becomes "what depends on this element?", the information is already part of the product context.

DEMO DATA
Dependencies graph
Capture produit VAST
à intégrer
SEARCH ACROSS PRODUCTS

Portfolio search

"Where do we use this component?" should not start a multi-day investigation.

A Product Security team rarely works on one isolated Asset. When a library is compromised, a supplier reports an issue or a technology must be removed, the important question immediately becomes cross-product: which Projects, Assets and versions are affected?

VAST lets teams search product knowledge across the portfolio. A library, component, CVE, license, technology, supplier or another criterion can become the starting point to find affected products and open their context directly.

This is valuable even before Risk Assessment: it reduces the time needed to understand the real scope of an issue and decide where effort should be focused.

DEMO DATA
Portfolio Search
Capture produit VAST
à intégrer
FROM VULNERABILITY TO RISK

Once products are known, security becomes actionable.

Vulnerabilities, threats and risk are read in the real context of the product — not as isolated feeds.

CVE
VEX
Threat
Risk
VULNERABILITY IN PRODUCT CONTEXT

Vulnerabilities & VEX

A CVE becomes useful when you know where it exists and what it means for the product.

Vulnerability feeds create alerts. They do not always know how a component is actually used inside your equipment. VAST places the vulnerability back into the Asset and its version: which component is affected, which products contain it, how it is used and which decisions have already been made.

Teams can then investigate exploitability, document the conclusion, follow remediation and produce VEX information when needed. New information does not replace the history; it enriches product knowledge and helps show which decisions may deserve another review.

Vulnerability · VEX
CVEReported vulnerability
Product contextWhere is the component used?
VEXDocumented exploitability status
VAST THREAT ENGINE

Threat Engine

Identify the threats that deserve attention for the product, without turning the assessment into a catalog exercise.

A generic threat database may contain a large amount of information without telling teams which threats actually matter for a specific product. VAST Threat Engine uses the context already built around the Asset to help identify relevant threats.

Threat knowledge can come from complementary spaces: VAST knowledge, recognized sources such as MITRE ATT&CK, and organization-specific catalogs when the business, technology or previous experience requires more targeted coverage.

The website does not need to explain the internal mechanics. What matters to the user is simple: threat knowledge joins product knowledge instead of living in a separate database.

Threat Engine
Composition & usageWhat the product contains
Relevant threatsFiltered by real context
PrioritizationWhat deserves attention
RISK ASSESSMENT

Risk Assessment

Risk Assessment becomes stronger when it does not begin by rebuilding the product context.

Risk Assessment remains a major VAST capability, but it comes after understanding the Asset. The analyst starts with structured context: product, version, components, dependencies, data, interfaces, vulnerabilities and relevant threats. More time can therefore be spent on reasoning and less time collecting the same information again.

The assessment also stays connected to the facts that supported it. When the product changes, VAST can help identify the elements that may affect an existing assessment and focus the review where it matters. Important decisions remain under human control and their justification stays traceable.

Risk Assessment
AssetProduct knowledge
Vuln + ThreatSecurity context
Reliable riskGrounded in the real product
FROM ASSET TO PORTFOLIO

Dashboards & portfolio visibility

See one product in detail while keeping visibility across the portfolio.

The same platform must answer very different questions. An Asset Manager wants to know whether the technical knowledge of a product is complete. A Product Security team wants to see open vulnerabilities or shared components. A manager wants to identify issues that cross several projects. An analyst wants to open the items that need review.

VAST dashboards let users move from a consolidated view to the Project, the Asset and the source information. The goal is not to create a decorative score, but to make the state visible and support drill-down to the context behind each indicator.

DEMO DATA
Dashboards
Capture produit VAST
à intégrer
CYBER RESILIENCE ACT

CRA compliance & evidence

The CRA reinforces an operational reality: manufacturers need to keep knowing and following their products after they reach the market.

Compliance does not begin with a final report. It first depends on knowing which products and versions exist, what they contain, which vulnerabilities affect them, which decisions were made and which evidence can still be found over time.

VAST was designed around that continuity. Asset Inventory, versioning, portfolio search, vulnerability management, threat analysis, Risk Assessment and Evidence Management work from the same product knowledge. The platform helps teams structure and maintain the information needed for their CRA process without reducing compliance to a checklist.

See how VAST supports CRA readiness

DEMO DATA
CRA · Evidence & Actions
Capture produit VAST
à intégrer
REPORTING & EVIDENCE

Reporting & evidence

Evidence is much easier to produce when information has been maintained throughout the lifecycle.

When Projects, Assets, versions, assessments and decisions live in the same environment, reporting no longer starts with manual data collection. VAST can produce views and reports from the known product state and keep the connection to the information behind them.

Sharing remains controlled. A customer, integrator or auditor may need to understand a decision without receiving the complete internal architecture of the product.

Share the ingredients, not the recipe.

DEMO DATA
Reporting & Evidence
Capture produit VAST
à intégrer
CONNECT YOUR EXISTING WORK

Integrate with your tools

Your engineering tools remain your engineering tools.

VAST is not designed to replace ALM, PLM, development tools, pipelines or SBOM sources. Those systems continue to produce the information that describes the product. VAST brings the cybersecurity-relevant information together, adds the context teams need and connects it to the activities that use it.

The platform becomes a cybersecurity continuity layer across information that already exists, without asking teams to rebuild their engineering work inside a security tool.

DEMO DATA
Integrations
Capture produit VAST
à intégrer

Show us one of your products. Start by seeing what VAST can understand about it.

From a Project and an Asset, VAST builds the context that supports search, version tracking, dependency analysis, vulnerability handling, threat and risk assessment, and evidence over time.

FR EN